PT-2025-41711 · Unknown · Rainygao Docsys

Tta0

·

Published

2025-10-12

·

Updated

2025-10-12

·

CVE-2025-11631

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions RainyGao DocSys versions up to 2.02.36
Description A flaw exists in RainyGao DocSys that allows for path traversal. This issue is related to the file /Doc/deleteDoc.do and involves manipulating the path argument. The attack can be initiated remotely. The exploit has been publicly disclosed, and the vendor was informed but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-11631

Affected Products

Rainygao Docsys